Supplier Risk Analyst

Newcastle upon Tyne
3 days ago
Create job alert

Supplier Risk Analyst

Location: Newcastle upon Tyne (Hybrid 2 days on site)

Contract Length: 6‑month contract (possible extension)

Day Rate: £450 per day inside IR35 via umbrella

About the Opportunity

We're supporting a major organisation through a large‑scale separation and transformation programme, and we're looking for an experienced Supplier Risk Analyst to join the team responsible for onboarding a significant number of new third‑party suppliers.

This role is ideal for someone who enjoys structured work, thrives under pressure, and feels confident engaging with suppliers and internal risk specialists. You'll play a meaningful part in a programme with firm regulatory deadlines, giving you exposure across information security, operational resilience, IT continuity, legal, procurement, and wider governance teams.

Key Roles and Responsibilities

Leading the supplier due‑diligence process for new suppliers joining the organisation as part of a separation programme.
Reviewing onboarding forms and clarifying service scope, criticality, and resilience requirements with business stakeholders.
Coordinating and facilitating meetings with suppliers and internal SMEs to complete due‑diligence questionnaires and collate evidence.
Assessing and escalating risks across information security, operational resilience, data privacy and IT service continuity.
Managing and updating Kanban boards (Microsoft Planner), trackers and workplans.
Presenting risk findings clearly and concisely for senior stakeholders, translating technical information into accessible summaries.
Handling supplier pushbacks professionally and keeping delivery aligned with strict programme deadlines.
Working collaboratively across legal, procurement, compliance, data privacy, business owners and technology teams.

Key Skills & Experience

Experience in supplier risk, third‑party risk, assurance, or operational resilience.
Knowledge across at least one core risk domain:
Information Security
IT Service Continuity
Operational Resilience
Excellent stakeholder engagement skills, including managing external suppliers.
Strong planning, coordination and PMO‑style organisational skills.
Confident communicator able to summarise risk and technical issues clearly.
Comfortable working in high‑pressure, deadline‑driven
Understanding of regulatory frameworks such as operational resilience standards and sector‑specific supervisory statements.
Relevant certifications such as CISA (highly desirable) or CISSP (nice‑to‑have).
Experience of risk‑related PMO work.
Strong Excel skills; MS Project familiarity helpful but not required.

Please note: Due to the high volume of applications, only successful candidates will be contacted. If you do not hear from us within 48 hours, unfortunately, your application has not been successful on this occasion. However, we may retain your details for any future suitable vacancies and contact you accordingly.

Pontoon is an employment consultancy. We put expertise, energy, and enthusiasm into improving everyone's chance of being part of the workplace. We respect and appreciate people of all ethnicities, generations, religious beliefs, sexual orientations, gender identities, and more. We do this by showcasing their talents, skills, and unique experience in an inclusive environment that helps them thrive. If you require reasonable adjustments at any stage, please let us know and we will be happy to support you.

We use generative AI tools to support our candidate screening process. This helps us ensure a fair, consistent, and efficient experience for all applicants. Rest assured, all final decisions are made by our hiring team, and your application will be reviewed with care and attention

Related Jobs

View all jobs

Junior Information Security Analysist

IT Information Security Analyst - Compliance

OT Cybersecurity Engineer

GRC Analyst

Test Analyst

Network Security Engineer

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cyber Security Jobs for Career Switchers in Their 30s, 40s & 50s (UK Reality Check)

If you’re thinking about switching into cyber security in your 30s, 40s or 50s, you’re in good company. Across the UK, organisations of all sizes are hiring people from diverse backgrounds to protect systems, data & customers. But with hype around “hackers” & quick-win courses, it’s hard to separate reality from fiction. This guide gives you a UK reality check: which roles genuinely exist, what employers actually want, how training really works, what to expect on salary & progression & whether age matters. Whether you come from finance, project management, operations, law, HR or customer service, there is a credible route into cyber security if you approach it strategically.

How to Write a Cyber Security Job Ad That Attracts the Right People

Cyber security is now a board-level priority for organisations across the UK. From financial services and healthcare to critical infrastructure, SaaS platforms and the public sector, demand for skilled cyber security professionals continues to grow. Yet despite this demand, many employers struggle to attract the right candidates. Cyber security job adverts often generate large volumes of applications, but few are a genuine match. Meanwhile, experienced security engineers, analysts and architects quietly ignore adverts that feel vague, unrealistic or disconnected from real security work. In most cases, the problem is not a lack of talent — it is the quality of the job advert. Cyber security professionals are trained to assess risk, spot weaknesses and question assumptions. A poorly written job ad signals organisational immaturity and weak security culture. A well-written one signals seriousness, competence and trust. This guide explains how to write a cyber security job ad that attracts the right people, improves applicant quality and positions your organisation as a credible security employer.

Maths for Cyber Security Jobs: The Only Topics You Actually Need (& How to Learn Them)

If you are applying for cyber security jobs in the UK it can feel like “real security people” must be brilliant at maths. The reality is simpler: most roles do not need degree-level pure maths. What they do need is confidence with a small set of practical topics that show up repeatedly in day-to-day work across SOC, incident response, cloud security, AppSec, threat detection, IAM & security engineering. This guide strips the maths down to what actually helps you get hired. It includes a 6-week learning plan plus portfolio projects you can publish to prove the skills. You will focus on: Number systems & bitwise thinking (binary, hex, bytes, XOR) Modular arithmetic basics (enough to understand how modern crypto “works”) Probability & statistics for detection, triage & risk Discrete maths for logic, sets, graphs & complexity Security maths habits: estimation, false positive control & evidence-led reporting You will not waste time on heavy theory that rarely appears in junior or mid-level cyber security roles.